# Prove SonicWall is working — first tool + proof field

Source: https://ai.techclick.in/blog_sonicwall_evidence_desk
Markdown: https://ai.techclick.in/blog_sonicwall_evidence_desk.md
Publisher: Techclick Infosec Pvt Ltd

How you prove SonicWall is working: Connection Monitor / session, Log > Monitor, Access Rule hit, VPN status, Capture ATP. Five tickets with first tool and one official SonicOS proof field.

Quick answer (say this out loud)

    Connections  answers “did this 5-tuple become a session on this NSa?”  MONITOR | Logs &gt; System Logs  (operators still say  Log &gt; Monitor ) answers “which  Access Rule Name  wrote the event?”  Access Rule traffic statistics  answers “did that named rule actually increment?”  Currently Active VPN Tunnels  answers “is this site-to-site in the active table — and is the subnet in Local / Destination Networks?”  Capture ATP  answers “is the file still waiting on a verdict, or already judged?” A green tile is not a session. An Allow is not a hit. An IPsec SA in the list is not the printer subnet.

## 1. Why “is it working?” is five questions

  Concept:  Operators collapse five failures into one sentence. The packet never became a connection. A Deny (or Discard) wrote a log. The rule you are staring at has zero traffic statistics since Restore. The tunnel is in Currently Active VPN Tunnels while 10.50.0.0/24 is missing from Destination Networks. Capture ATP is holding the download until a verdict returns. Those are five first clicks.

  Path:  Write the 5-tuple + UTC. Then pick the tile: Connections → System Logs → Access Rule hits → Currently Active VPN Tunnels → Capture ATP. The factory taught the stamps (X-port, zone, access rule, NAT, ARP, DPI-SSL, proxy ID). Here you learn the five SonicOS tools you actually open when someone asks you to prove the firewall is working.

  Do:  Quote one official field before you change POLICY | Capture ATP, bounce IKE, or add a second LAN→WAN Allow. Lab identities below are RFC 5737 / example.com only.

   Hero · five tiles, one ticket

   Notice: five tiles, not one “SonicOS dashboard.” You pick the tile that matches the question, then you quote one official field.

   Interview line

   If they say “prove SonicWall is working,” do not say “I opened the Management Interface.” Say: “I prove the session on  MONITOR | Tools &amp; Monitors &gt; Connections  with  Src IP  +  Src Port , the event with System Logs  Access Rule Name , the rule with Access Rule traffic statistics, the tunnel with  Currently Active VPN Tunnels  plus Local / Destination Networks, and the file with Capture ATP verdict / Block until verdict.”

   Name drift (official)

   Night-shift veterans still say  Connection Monitor  and  Log &gt; Monitor  — those are the SonicOS 6 labels. SonicOS 7 / 8 technical documentation titles the same work  MONITOR | Tools &amp; Monitors &gt; Connections  and  MONITOR | Logs &gt; System Logs . This desk uses both names on purpose. The fields did not move; the left-nav did.

## 2. Mental model — five proof tools

 Memorise five named objects before you click. Each tool is allowed to prove one thing. Over-claiming a field is how you disable Capture ATP at 02:00 for a SYN that never left X0.

#### 1 · Connection Monitor / session

     SonicOS 7/8:  MONITOR | Tools &amp; Monitors &gt; Connections . IPv4 or IPv6. Official columns include  Src IP ,  Src Port ,  Dst MAC ,  Dst Vendor . Filter the table. Proves the appliance built (or never built) a connection. Does not prove which Access Rule wrote the log.

#### 2 · Log > Monitor

     SonicOS 7/8:  MONITOR | Logs &gt; System Logs . Official column:  Access Rule Name  — “Name of the Access Rule triggering the event, if any.” Also  Access and IDP Rules . Filter icon + Grid Settings. One event. Not a hit counter.

#### 3 · Access Rule hit

      POLICY | Rules and Policies &gt; Access Rules . Display  traffic statistics  from Settings &gt; Grid Settings.  Restore  restarts the counts. Zone Matrix / From Zone–To Zone first. Action is Allow, Deny, or Discard. A written Allow with zero stats is not a hit.

#### 4 · VPN status

      NETWORK | IPSec VPN &gt; Rules and Settings . Proof object:  Currently Active VPN Tunnels  (Refresh at the top). Policy Type Site to Site. Then open the policy Network tab:  Local Networks  /  Destination Networks . Active ≠ that subnet.

#### 5 · Capture ATP

      POLICY | Capture ATP &gt; Settings  plus  Dashboard | Capture ATP . Official hold:  Block file download until a verdict is returned . Files can sit in  Files Blocked Until Completely Analyzed . GAV + Cloud Gateway Anti-Virus must be on or Capture ATP stops.

#### Hard words, once

      Connection  = the session row, not the cable.  Access Rule Name  = the log column.  Traffic statistics  = the hit counter.  Currently Active VPN Tunnels  = the live table.  Verdict  = Capture ATP’s clean / malicious / still-analyzing answer. Classic Mode uses Access Rules; Policy Mode uses a unified Security Policy table — same isolate idea.

   Flow 1 · five tools, one question each

       Five SonicWall proof tools and the one question each is allowed to answer

- Write 5-tuple + UTC first · then pick the tool Is the firewall even working? five SonicOS questions, not one Connections This 5-tuple a session? Src IP + Src Port Dst MAC · Dst Vendor Tools & Monitors not a verdict System Logs Which rule wrote it? Access Rule Name Access and IDP Rules MONITOR | Logs not a hit count Rule hit Did this rule increment? traffic statistics Grid Settings · Restore Access Rules table Allow ≠ hit VPN status This tunnel active? Currently Active Local / Dest Networks IPSec VPN > Rules not the printer /24 Capture ATP This file judged? verdict Block until verdict POLICY | Capture ATP not a missing Allow Empty Connections is data. It usually means the packet never became a session. Do not invent a Capture ATP outage from an empty session table. Start at X-port / zone / Access Rule — the factory. Read left → right. Each box is allowed one claim. If you cannot name the official field, you are not proving — you are guessing. Say this out loud I prove the session, then the log row, then the hit counter, then the active tunnel plus proxy ID, then the ATP verdict. I do not disable Capture ATP, bounce IKE, or add Any-Any until I can quote the field that made me do it. ## 3. Decision flow — ticket → first tool Flowchart first. Do not open POLICY | Capture ATP until a diamond says the file is the question. Path · pick the branch before the menu Notice: the diamond is the ticket. The path is the SonicOS tool. The field comes last. Do not reverse that order. Flow 2 · first-tool diamond Decision diamond from SonicWall symptom to first proof tool Symptom first · tool second · field third What must we prove? A live session? or already inside? HTTPS “dead” Connections Src IP · Src Port One flow denied System Logs Access Rule Name “Rule 14 allows” Access Rule hit traffic statistics SA “up”, /24 dead VPN status Active + Networks Download hung Capture ATP verdict / hold Empty Connections → stop. There is no Access Rule Name to chase yet. Fix X-port / zone / first-match rule / ARP (factory). Then re-open Connections. Diamond = decision. Do not disable Capture ATP from the bottom box. Older tenants still say Connection Monitor and Log > Monitor. Official 7/8 path is MONITOR | … Read the diamond first. A hung download never starts on Access Rules. A dead printer /24 never starts on Capture ATP. Empty Connections never starts on a new Allow. ## 4. How to choose — first tool + proof field Print this next to the SonicOS tab. If you cannot recite the proof field, you are not ready to change anything. If the ticket says… First tool (official path) Proof field Do not open first Laptop / “is the firewall even working?” / HTTPS stuck MONITOR | Tools & Monitors > Connections (Connection Monitor). IPv4 or IPv6. Use Filter. A row for this 5-tuple: official Src IP + Src Port (plus Dst MAC / Dst Vendor when L2 matters) POLICY | Capture ATP One flow denied or discarded after a policy change MONITOR | Logs > System Logs (Log > Monitor). Filter icon. Access Rule Name of the Access Rule triggering the event (+ Access and IDP Rules) A second LAN→WAN Allow “Rule 14 already allows” / “that rule never hits” POLICY | Rules and Policies > Access Rules → Settings > Grid Settings → traffic statistics Traffic statistics on that named rule since last Restore . Action = Allow / Deny / Discard Disable GAV Site-to-site “up”, one remote subnet dead NETWORK | IPSec VPN > Rules and Settings → Currently Active VPN Tunnels (Refresh) Tunnel present in Currently Active VPN Tunnels , then Local Networks / Destination Networks on the policy Bounce IKE / change Phase 1 Download hung; “disable Capture ATP” POLICY | Capture ATP > Settings and Dashboard | Capture ATP Block file download until a verdict is returned / Files Blocked Until Completely Analyzed / the verdict A new Access Rule, or unchecking GAV Factory hand-off If Connections is empty, you are not on this desk’s ticket 2–5 yet. You are back in the factory: name the X-port and zone on Network | Interfaces , then the zone-pair Access Rule, then NAT, then ARP on the egress X-port. Lesson: SonicOS speaks X0 and X1 . Allow is not a session. Incomplete ARP ends the policy debate. ## 5. Runbook Side A → B → C Side A proves the session and the Access Rule hit. Side B proves the log store. Side C proves the overlay — IPsec and Capture ATP. On a messy Sev-2, do them in this order until a field lights up. Every step cites SonicWall technical documentation. ### Side A — Session + Access Rule hit #### Open Connections, not Capture ATP Path: MONITOR | Tools & Monitors > Connections . Official: Viewing Connections — click IPv4 or IPv6 . The appliance “maintains a connections log for tracking all active connections.” Use Filter so the table shows only the ticket 5-tuple. Source: SonicOS 7.0 / 7.3 / 8 Monitor — Connections.

- #### Quote the official columns that close a session ticket Documented Viewing Connections columns include Src IP (IP address of the source device), Src Port (port number of the source device), Dst MAC , Dst Vendor . Match 10.10.8.22 (lab) to the destination you were given. A matching row means SonicOS built a connection. An empty filtered table means the packet never became a session — stop. Do not hunt a verdict.

- #### If someone claims “the rule allows,” open traffic statistics Path: POLICY | Rules and Policies > Access Rules . Use the Zone Matrix Selector or From Zone / To Zone. Open Settings > Grid Settings and display traffic statistics . Official: to restart the counts, click Restore . Quote the named rule’s statistics after a reproduce. Action values on the rule are Allow, Deny, or Discard. Source: SonicOS 7.1 Rules and Policies for Classic Mode — Display Traffic Statistics.

- #### Empty session + zero statistics = factory, not ATP If Connections has no row and the intended rule’s traffic statistics did not increment, the packet never reached that rule. Confirm X-port / Zone on Network | Interfaces , then the first-match Access Rule for that zone pair. That is the factory, not this desk’s Capture ATP ticket.

     https://192.168.168.168/sonicos · MONITOR | Tools &amp; Monitors &gt; Connections

     Training mock · not live

       MONITOR / Tools &amp; Monitors / Connections / IPv4

### Connections

        IPv4  IPv6

          Filter  Src IP = 10.10.8.22

          IP type  IPv4

           Src IP  Src Port  Dst MAC  Dst Vendor

            10.10.8.22  51844  00:53:00:11:22:33  Lab-ISP
            10.10.8.40  44312  00:53:00:aa:bb:cc  Lab-Core

       Official Viewing Connections columns shown. Empty filtered table = no session. Training mock · RFC 5737 / lab MACs only.

        Clear Filter  Filter

    Source:  SonicOS 7.0 Tools &amp; Monitors — Viewing Connections; SonicOS 7.3 / 8 Monitor — Connections ( Src IP ,  Src Port ,  Dst MAC ,  Dst Vendor ; IPv4 / IPv6; Filter). Lab identities only.

### Side B — Log > Monitor (System Logs)

- #### Open System Logs, not the policy editor Path: MONITOR | Logs > System Logs . Operators: Log > Monitor . Official: navigate to MONITOR | Logs > System Logs, then use the Filter icon. Grid Settings chooses which columns display. Source: SonicOS 7.3 Monitor — System Logs display options / filter view / functions.

- #### Read Access Rule Name — that is the ticket Official column: Access Rule Name — “Name of the Access Rule triggering the event, if any.” Also documented under Access and IDP Rules . Filter source 10.10.8.22 (lab) + the UTC window. Quote the name, not “a deny somewhere.”

- #### Empty System Logs is not “SonicWall is down” If Connections already showed a session and System Logs has no row, check Grid Settings, the Filter, and the time window. Logging can be off on that Access Rule. That is a Track / logging problem — not a reason to add Any-Any “so we get a log.” Packet Monitor (MONITOR | Tools & Monitors > Packet Monitor) is a different isolate tool; it is not one of this desk’s five first tiles.

     https://192.168.168.168/sonicos · MONITOR | Logs &gt; System Logs

     Training mock · not live

       MONITOR / Logs / System Logs

### System Logs

          Filter  Source = 10.10.8.22

          Time range  Last 15 minutes

           Time (UTC)  Priority  Category  Access Rule Name

            01:41:08  Inform  Network Access  LAN WAN HTTPS Allow
            01:42:11  Warning  Network Access  LAN WAN Cleanup Deny

        Reset filters  Filter

    Source:  SonicOS 7.3 Monitor — System Logs (display options, filter view, functions). Official column  Access Rule Name  — name of the Access Rule triggering the event, if any. Lab identities only.

  Side B — fields you write in the ticket  Path:              MONITOR | Logs &gt; System Logs   (aka Log &gt; Monitor)
Filter:            Source 10.10.8.22 + UTC window
Quote:             Access Rule Name = LAN WAN Cleanup Deny
If empty + session: Grid Settings / Filter / logging on that rule
Do not:            add Any-Any “to generate a log”

### Side C — VPN status + Capture ATP

- #### Prove the tunnel from Currently Active VPN Tunnels Path: NETWORK | IPSec VPN > Rules and Settings . Official: a list of currently active VPN tunnels is displayed; Refresh the active tunnels at the top of the Policies view. Policy Type on the General screen includes Site to Site . Source: SonicOS/X 7 IPSec VPN — Currently Active VPN Tunnels; site-to-site policies.

- #### Then open Local Networks / Destination Networks Active in the table is not the printer subnet. Open the VPN Policy → Network. Quote Local Networks and Destination Networks (the proxy ID / interesting traffic). Official: when adding VPN Policies, SonicOS auto-creates non-editable Access Rules so traffic can traverse Trusted Zones and the VPN Zone — those auto-rules are not a substitute for listing 10.50.0.0/24. Do not bounce IKE first.

- #### If the ticket is a hung download, prove the verdict Path: POLICY | Capture ATP > Settings . Official enable set: Capture ATP, Gateway Anti-Virus (GAV), and Cloud Gateway Anti-Virus. Official hold: Block file download until a verdict is returned — “ensures no packets get through until the file is completely analyzed.” Dashboard: Dashboard | Capture ATP (status of files sent to the backend). Files can remain in Files Blocked Until Completely Analyzed . Capture ATP stops working when GAV or Cloud GAV is disabled — unchecking GAV is not isolate. Source: SonicOS 7.0 / 7.1 / 8 Capture ATP; SonicOS 7.3 Monitor Dashboard — Capture ATP.

     https://192.168.168.168/sonicos · POLICY | Capture ATP &gt; Settings

     Training mock · not live

       POLICY / Capture ATP / Settings

### Capture ATP

          Capture ATP  Enabled

          Gateway Anti-Virus  Enabled

          Cloud Gateway Anti-Virus  Enabled

          Block file download until a verdict is returned  On

Dashboard | Capture ATP (lab)

 Files Blocked Until Completely Analyzed: 1

file=finance-q4.xlsx  src=10.10.8.22  state=analyzing

 Do not uncheck GAV — Capture ATP stops when GAV or Cloud GAV is disabled.

    Source:  SonicOS 7.0.1 / 7.1 / 8 Capture ATP (enable GAV + Cloud GAV; Block file download until a verdict is returned; Files Blocked Until Completely Analyzed); SonicOS 7.3 Monitor Dashboard — Capture ATP. Training mock · not live.

   Green success on each side

- Side A session: Connections Filter returns the ticket Src IP + Src Port . Side A hit: the named Access Rule’s traffic statistics incremented after Restore + reproduce.

- Side B: System Logs Access Rule Name matches the rule you intend to change (or the Deny you must own).

- Side C tunnel: the policy is in Currently Active VPN Tunnels and the dead subnet is listed under Destination Networks — or you quoted that it is missing.

- Side C file: Dashboard | Capture ATP shows a verdict, or you quoted Block until verdict / Files Blocked Until Completely Analyzed as the hold.

## 6. Five tickets as full stories

 These five land every quarter. Memorise first tool + proof field. Times and identities below are lab-only.

   Proof · named field, then Closed

   Notice: Connections can already show a session while Capture ATP is still holding the file. That is an ATP ticket, not a missing Allow.

     Ticket  Symptom  First tool  Proof field

       SWEVD-01   “Is the firewall even working?” Finance HTTPS stuck  MONITOR | Tools &amp; Monitors &gt; Connections   Src IP  +  Src Port  row — or an empty Filter
       SWEVD-02   After a cleanup, one host cannot reach SaaS  MONITOR | Logs &gt; System Logs   Access Rule Name  on that event
       SWEVD-03   “Rule 14 already allows” but the app never loads  POLICY | Rules and Policies &gt; Access Rules  Traffic statistics since Restore (zero vs increment)
       SWEVD-04   IPsec “up”, printers on 10.50.0.0/24 dead  NETWORK | IPSec VPN &gt; Rules and Settings  Currently Active VPN Tunnels + Destination Networks
       SWEVD-05   Download hung; L1 wants Capture ATP off  POLICY | Capture ATP + Dashboard | Capture ATP  Block until verdict / Files Blocked Until Completely Analyzed / verdict

### SWEVD-01 — Prove the session (Connections)

  01:42 · P2.  Priya: Finance HTTPS to  198.51.100.80:443  is stuck. Someone pasted a green HOME / System Status screenshot. L1 already drafted “disable Capture ATP.”

  First tool:   MONITOR | Tools &amp; Monitors &gt; Connections  → IPv4 → Filter  Src IP = 10.10.8.22  (lab host).

  If empty:  SonicOS never built a connection. Quote the empty Filter. Next station is the factory — X-port / zone / first-match Access Rule / ARP on the egress X-port — not POLICY | Capture ATP. The factory dummy lab would then print  state=SYN_SENT  and  bytes=…/0 ; that is isolate language for “forward done, return not done.” Official Connections proof is still the row (or its absence) with  Src IP  +  Src Port .

  If a row exists:  you proved a session. You are now allowed to open System Logs for  Access Rule Name , or Capture ATP if the symptom is a hung file. The Connections row is not a verdict.

  Trap

 Do not trust a colleague’s Connections tab from a different NSa or the idle HA peer. Official HA: retest on the current active unit. Empty tables on standby are expected.

### SWEVD-02 — Prove the event (System Logs)

  02:05 · P2.  A cleanup change shipped at 01:18. Outlook on the Web opens from some desks. Priya’s host cannot reach  198.51.100.80 . Someone wants “another LAN→WAN Allow at the top.”

  First tool:   MONITOR | Logs &gt; System Logs . Filter Source =  10.10.8.22 , last hour.

  Proof field:   Access Rule Name  =  LAN WAN Cleanup Deny  (lab). That name is the ticket. Change that one rule — or the object it missed — then reproduce and re-read the same column. If Category points at an IDP / security-service event under Access and IDP Rules, you are not in a missing-Allow story.

  Close

 I would not add a second LAN→WAN Allow. I would quote  Access Rule Name  on the failing 5-tuple. A saved rule is not proof until the same Filter returns the intended name after reproduce.

### SWEVD-03 — Prove the hit (Access Rule traffic statistics)

  02:20 · P2.  L1: “Rule 14 already Allows HTTPS. SonicWall is broken.” They are looking at the Action column, not the counters.

  First tool:   POLICY | Rules and Policies &gt; Access Rules . Zone pair LAN → WAN. Settings &gt; Grid Settings → display traffic statistics. Note the counts. Click  Restore  if you need a clean window. Reproduce once. Re-read the same rule.

  Proof field:  traffic statistics still  zero  after reproduce → this rule never saw the packet (wrong zone pair, shadowed by a higher-priority rule, or the session never started — go back to Connections). Statistics increment and Action = Allow → the rule is doing its job; the next station is ARP / NAT / DPI-SSL (factory) or Capture ATP if the file is the hold.

  Close

 Allow is permission. Traffic statistics are the hit. I would paste the rule name + Action + statistics since Restore. I would not add Any-Any on top of a rule that already Allows and already increments.

### SWEVD-04 — Prove the tunnel (Currently Active VPN Tunnels)

  02:40 · P2.  DC printers on  10.50.0.0/24  are dead. The channel screenshot shows the site-to-site policy Enabled. L1 wants IKE bounced.

  First tool:   NETWORK | IPSec VPN &gt; Rules and Settings . Refresh. Confirm the policy is in  Currently Active VPN Tunnels .

  Proof field:  the tunnel  is  in the active table, and Destination Networks does  not  list  10.50.0.0/24 . Active ≠ the subnet. Official Network objects on the VPN Policy are Local Networks and Destination Networks. Auto-added Access Rules between Trusted Zones and the VPN Zone only pass what the policy’s networks include. Do not bounce IKE. Do not change Phase 1.

  Trap

 Restarting a healthy IKE SA is change-control, not isolate. A missing Destination Network is a Network-tab ticket. Quote the object list.

### SWEVD-05 — Prove the file (Capture ATP)

  03:00 · P3.  Finance cannot download  finance-q4.xlsx . Connections already shows  Src IP 10.10.8.22 . System Logs  Access Rule Name  is the HTTPS Allow. L1 typed “disable Capture ATP” in the channel.

  First tool:   POLICY | Capture ATP &gt; Settings  and  Dashboard | Capture ATP .

  Proof field:   Block file download until a verdict is returned  is On, and the file is in  Files Blocked Until Completely Analyzed  (or the dashboard shows analyzing / the later verdict). Official: that option holds packets until analysis finishes. Official: Capture ATP stops when GAV or Cloud Gateway Anti-Virus is disabled — unchecking GAV to “make the download work” turns the sandbox off. Wait for the verdict, or use a documented exclusion after change-control — do not disable the service from a Sev-3 download.

  Close

 I would leave Access Rules alone. I would paste Block until verdict + the dashboard file state. A session + an Allow + a hold is Capture ATP doing what you asked.

## 7. Traps + close-the-ticket proof

 Weak closes reuse a screenshot. Strong closes reuse a named SonicOS field.

     You see  Weak close  Strong close

      Green HOME / System Status tile  “SonicWall is working”  Connections row for the 5-tuple:  Src IP  +  Src Port
      Empty Connections Filter  Disable Capture ATP  Quote the empty table; factory: X-port / zone / rule / ARP
      Access Rule Action = Allow  “Policy is fine”  Traffic statistics since Restore — Allow ≠ hit
      System Logs empty, session exists  Any-Any “to get a log”  Grid Settings + Filter + logging on that rule; quote  Access Rule Name  when it appears
       Access Rule Name  = Cleanup Deny  Second LAN→WAN Allow at the top  Change that named rule; re-read the same column
      VPN policy Enabled  Bounce IKE  Currently Active VPN Tunnels + Local / Destination Networks
      Tunnel in Currently Active, one /24 dead  “IPsec is down”  Quote the missing Destination Network object
      Download hung, session + Allow exist  Uncheck GAV / Capture ATP  Block until verdict / Files Blocked Until Completely Analyzed / verdict
      Idle HA peer, empty Connections  “The pair is down”  Retest the current active unit — idle standby is expected
      Capture ATP “not working”  Reboot the NSa  Official: it stops when GAV or Cloud GAV is disabled. Re-read Settings.

   Proof checklist before you leave the bridge

- UTC window written next to the tool you opened.

- Unit proved: current active NSa, not the idle HA peer.

- Session proved when the ticket is “is the firewall even working?”: Connections Src IP + Src Port (or the empty Filter).

- One transaction quoted: System Logs Access Rule Name , or Access Rule traffic statistics since Restore, or Currently Active VPN Tunnels + Destination Networks, or Capture ATP verdict / hold.

- Factory station named if Connections is empty (X-port / zone / rule / ARP).

- Next tool named — or change-control owner named. No Any-Any, no GAV uncheck, no IKE bounce without residual control.

   Interview close

   I name the question, then the first tool, then one official field. Connections proves the session. System Logs proves  Access Rule Name . Access Rule traffic statistics prove the hit. Currently Active VPN Tunnels plus Local / Destination Networks prove the site-to-site. Capture ATP proves the file hold / verdict. I do not disable Capture ATP, bounce IKE, or add Any-Any until that field is on the ticket. Factory model:  SonicOS speaks X0 and X1 .

## Knowledge check

   Six night-shift judgments. Each maps to a first tool or a proof field. Check answers, then Reset if you picked the wrong surface.

       Q1
       01:40. “Is the firewall even working?” HOME looks green. You have not opened POLICY. First proof?

           Disable Capture ATP and retest HTTPS
           MONITOR | Tools &amp; Monitors &gt; Connections — Filter the 5-tuple and quote Src IP + Src Port (or the empty table)
           Add a LAN→WAN Any-Any at the top of Access Rules
           Paste the System Status tile into the ticket and close

       Correct:  b . Official Viewing Connections path and columns. A green tile is not a session. Re-read Side A steps 1–2 and SWEVD-01.

       Q2
       A cleanup change shipped an hour ago. One finance host cannot reach SaaS on tcp/443. Which proof field closes SWEVD-02?

           MONITOR | Logs &gt; System Logs: Access Rule Name on that event
           Currently Active VPN Tunnels only
           The HOME dashboard screenshot
           Dashboard | Capture ATP with no file in flight

       Correct:  a . Official System Logs column Access Rule Name is the Access Rule triggering the event. VPN and ATP are different tickets. Re-read Side B and SWEVD-02.

       Q3
       L1 says “Rule 14 already Allows HTTPS.” The app still fails. First tool + field?

           Uncheck Gateway Anti-Virus so Capture ATP “gets out of the way”
           Bounce IKE on every site-to-site policy
           POLICY | Rules and Policies &gt; Access Rules — display traffic statistics (Grid Settings); Restore, reproduce, quote the count
           Add a second Allow because Action already says Allow

       Correct:  c . Official: Settings &gt; Grid Settings displays traffic statistics; Restore restarts the counts. Allow is not a hit. Re-read Side A step 3 and SWEVD-03.

       Q4
       Site-to-site looks Enabled. Printers on 10.50.0.0/24 are dead. First tool + proof?

           Disable Capture ATP for the VPN zone
           NETWORK | IPSec VPN &gt; Rules and Settings: Refresh Currently Active VPN Tunnels, then quote Local Networks / Destination Networks
           Bounce IKE immediately so Phase 1 renegotiates
           Add Any-Any from LAN to WAN because auto-added VPN rules must be broken

       Correct:  b . Official Currently Active VPN Tunnels + Local / Destination Networks. Auto-added Access Rules only pass listed networks. Re-read Side C steps 1–2 and SWEVD-04.

       Q5
       Connections already shows Src IP 10.10.8.22. Access Rule Name is the HTTPS Allow. The xlsx download never finishes. What do you do first?

           Add a second LAN→WAN Allow for the same host
           Declare the NSa down because HOME CPU is not 0%
           Uncheck Gateway Anti-Virus so the file bypasses the cloud
           Leave the Access Rule alone. Open POLICY | Capture ATP and Dashboard | Capture ATP — quote Block until verdict / Files Blocked Until Completely Analyzed / the verdict

       Correct:  d . Official hold and dashboard. Unchecking GAV officially stops Capture ATP. Re-read Side C step 3 and SWEVD-05.

       Q6
       Connections Filter for the finance 5-tuple is empty. What is that empty table allowed to mean?

           No session was built — do not hunt Capture ATP first; return to X-port / zone / first-match Access Rule / ARP (the factory), then re-read Connections
           Currently Active VPN Tunnels must be empty
           Block until verdict is automatically On
           System Logs Access Rule Name overwrote the session table

       Correct:  a . Empty Connections is data: the packet never became a session. Factory first. Re-read Flow 2 bottom box and SWEVD-01.

       Check answers
       Reset

## Sources

- SonicOS 7.0 Tools & Monitors — Viewing Connections ( Src IP , Src Port , Dst MAC ; IPv4 / IPv6)

- SonicOS 7.0 Tools & Monitors — Filtering the Connection Log (Filter the Connections table)

- SonicOS 7.3 Monitor — Connections ( Src Port , Dst MAC , Dst Vendor )

- SonicOS 8 Monitor — Connections (connections log for all active connections)

- SonicOS 7.3 Monitor — System Logs display options ( Access Rule Name ; Access and IDP Rules; Grid Settings)

- SonicOS 7.3 Monitor — System Logs filter view (MONITOR | Logs > System Logs · Filter icon)

- SonicOS 7.3 Monitor — System Logs functions

- SonicOS 7.1 Rules and Policies (Classic) — Display Traffic Statistics (Settings > Grid Settings; Restore restarts counts)

- SonicOS 7.1 Rules and Policies (Classic) — Access Rules settings

- SonicOS 7.0 Rules and Policies (Classic) — Access Rules create (Zone Matrix Selector)

- SonicOS/X 7 IPSec VPN — Currently Active VPN Tunnels (Refresh)

- SonicOS/X 7 IPSec VPN — Site-to-site VPNs

- SonicOS/X 7 IPSec VPN — Create site-to-site (Policy Type Site to Site) (NETWORK | IPSec VPN > Rules and Settings)

- SonicOS/X 7 IPSec VPN — Auto-added Access Rules (Trusted Zones ↔ VPN Zone)

- SonicOS 7.0 Capture ATP

- SonicOS 7.1 Capture ATP — Enable (POLICY | Capture ATP > Settings; GAV + Cloud GAV)

- SonicOS 7.0 Capture ATP — Files blocked until a verdict

- SonicOS 7.0 Capture ATP — Disabling GAV (ATP stops when GAV or Cloud GAV is disabled)

- SonicOS 7.3 Monitor Dashboard — Capture ATP

- SonicOS 8 Capture ATP — Config

- SonicOS 7 About SonicOS — Capture ATP dashboard

 Related:  Blog 1 · SonicWall session factory  ·  SonicWall interview hub  ·  Dummy lab (simulator key sonicwall)  ·  Access rules and NAT  ·  DPI-SSL deep dive

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
